7.1
CVSSv3

CVE-2024-24595

Published: 05/02/2024 Updated: 13/02/2024
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

clear clearml -